Group 7: Automated Environment
30 original descriptive cases. Descriptive mix: 9 at 3 marks, 14 at 5 marks, 7 at 10 marks.
Original practice, not ICAI questions, official suggested answers or an official examiner scheme. Equivalent correct work is credited within the stated caps. Public practice availability is not full official question-bank completion.
AUD-G07-D001 · 3 marks
An ERP is not a guarantee of an easy audit
Aspen Goods moves from standalone accounting software to an integrated ERP linking sales, inventory and finance. Management says faster processing guarantees fewer audit risks and simpler work.
Required: Explain automation's benefits, complexity and the guarantee limit. (3 marks)
Show answer and marking
Non-credit errors
- No ERPmeanszerorisk guarantee.
Official ICAI concept sourceAUD-G07-D002 · 5 marks
Understand the environment before naming its risks
Bay Logistics uses a cloud billing application, local inventory software and a new interface version. Maintenance is outsourced; an administrator holds privileged access. The file only names the billing brand.
Required: Give five distinct areas of applied IT understanding to add. (5 marks)
Show answer and marking
Non-credit errors
- No five brandnamesinplaceofunderstanding.
Official ICAI concept sourceAUD-G07-D003 · 5 marks
Three control layers in one payment process
Cove Manufacturing restricts system changes and privileged access centrally. Its payment application rejects incomplete bank fields. A manager manually reviews a system-produced exception report, but source data reliability has not been assessed.
Required: Classify the three layers, explain their relationship and identify the report-review limit. (5 marks)
Show answer and marking
Non-credit errors
- No manualreviewmeansindependentofIT rule.
Official ICAI concept sourceAUD-G07-D004 · 3 marks
A back-end edit bypasses the visible screen
Delta Med's user-entry screen validates amounts, but a privileged operator can edit database values directly. The audit team says the entry check protects every possible data change.
Required: Identify the two relevant risk routes and the implication. (3 marks)
Show answer and marking
Non-credit errors
- No validationcoversallbackendchanges rule.
Official ICAI concept sourceAUD-G07-D005 · 10 marks
Build a six-risk IT response map
Estuary Foods' ERP review identifies:
A. Incorrect customer prices are imported even though multiplication is accurate.
B. A superuser can edit ledger data directly without an independent review.
C. Developers release price-rule changes without approval or testing.
D. A required tax-rule update has not been implemented; no current law conclusion is supplied.
E. The same person creates suppliers, approves payments and records them.
F. Backup jobs fail and restored data have not been checked.
No actual loss, fraud or reporting opinion conclusion is supplied.
Required:
(a) Map each issue to a distinct IT risk and a relevant control/evidence direction. (6 marks)
(b) Explain two implications for data/control reliance. (2 marks)
(c) State reporting and evidence boundaries. (2 marks)
Show answer and marking
Non-credit errors
- No sixgenericpasswordanswers.
- No inventedtaxlaworautomaticreport.
Official ICAI concept sourceAUD-G07-D006 · 5 marks
Four general-control objectives are different
Fjord Services has failed batch jobs/backups, untracked program changes, uncontrolled access and a new system implemented without testing. A trainee calls every issue only an application input check.
Required: Map the four general-control areas and explain their shared relationship to reporting. (5 marks)
Show answer and marking
Non-credit errors
- No allfouronlymandatoryfieldchecks.
Official ICAI concept sourceAUD-G07-D007 · 3 marks
A manual exception judgement can still matter
Grove Designs has rare complex transactions requiring discretion beyond its existing automated rules. Management says all manual elements must be removed because automated processes are always suitable.
Required: Explain judgement suitability, changing/exception conditions and the reliability limit. (3 marks)
Show answer and marking
Non-credit errors
- No allmanualmustberemoved rule.
Official ICAI concept sourceAUD-G07-D008 · 5 marks
A walkthrough is a plan, not all-period proof
Harbour Supplies' auditor proposes an end-to-end transaction walkthrough, observation under different user scenarios and inspection of application configuration. The team then calls all automated controls effective for the full year, without considering general controls.
Required: Explain the three understanding/testing actions, the role of corroborated inquiry and the control-reliance limit. (5 marks)
Show answer and marking
Non-credit errors
- No plannedwalkthroughalreadycompletedoruniversalproof.
Official ICAI concept sourceAUD-G07-D009 · 5 marks
Analytics can support work without proving fraud
Inlet Rentals uses an audit tool to reconcile extract counts, select transactions, recompute a balance and flag unusual journals. The junior says every flagged journal is fraud and the tool eliminates data validation.
Required: Explain four distinct uses and the evidence/conclusion boundary. (5 marks)
Show answer and marking
Non-credit errors
Official ICAI concept sourceAUD-G07-D010 · 10 marks
A report-driven control depends on its source
Juniper Shipping's manager manually reviews an ERP payment exception report. The report omits one interface batch, relies on a changed query never tested and can be edited by a privileged user. The application rejects missing supplier codes for normal input, but this does not cover the omitted batch. The auditor has only management's statement that the review is done monthly.
Required:
(a) Classify the manual report review, embedded validation and supporting controls, applying the distinctions. (3 marks)
(b) Analyse the three report/source weaknesses and propose relevant evidence work. (3 marks)
(c) Explain review-operation evidence and alternative audit work. (2 marks)
(d) State two scope/conclusion boundaries. (2 marks)
Show answer and marking
Non-credit errors
- No manualreviewfixesunreliablesource automatically.
- No inputvalidationcoversomittedinterfaces.
Official ICAI concept sourceAUD-G07-D011 · 3 marks
A sequence gap is not a sale by itself
An order application's sequence check identifies missing number 418. The team wants to record it as an omitted sale without checking cancelled orders or how numbers are assigned.
Required: Explain the control type, follow-up and conclusion limit. (3 marks)
Show answer and marking
Non-credit errors
- No gap automatically equals omitted revenue.
Official ICAI concept sourceAUD-G07-D012 · 5 marks
An approved limit can be poorly configured
A purchase application blocks approvals above each user's limit. The senior purchaser is incorrectly configured with an unlimited allowance; no review of settings is available. A valid supplier code is mandatory. Management says these two checks prove all purchases are authorised.
Required: Analyse the two checks, the setting weakness, supporting control work and the reliance limit. (5 marks)
Show answer and marking
Non-credit errors
- No mandatory code proves every purchase authorised.
Official ICAI concept sourceAUD-G07-D013 · 5 marks
A release ticket without a tested release
A pricing program was changed in June. A ticket approves the request, but the installed version differs from the tested version. No evidence shows what happened between testing and installation.
Required: Explain the objective and four applied evidence steps or limits. (5 marks)
Show answer and marking
Non-credit errors
- No approved ticket proves a different installed version tested.
Official ICAI concept sourceAUD-G07-D014 · 5 marks
Green backup status, unproven restoration
A monthly dashboard says all backups succeeded. The retained backup excludes the transaction database, and the recovery exercise only opened the application's login screen. Management calls this proof that all financial data can be restored.
Required: Explain the control area and four applied checks or conclusions. (5 marks)
Show answer and marking
Non-credit errors
- No login screen proves complete financial-data restoration.
Official ICAI concept sourceAUD-G07-D015 · 10 marks
Validate the population before trusting the tool
An audit extract for the financial year contains only the online sales channel. The ledger also includes store sales. The export job silently skips failed rows, duplicates rows on retries and maps credit-note amounts as positive. A trainee's tool reports that the extracted file's row count agrees with its own imported count, so the trainee proposes full reliance on the result. No reconciliation to source records has been done.
Required:
(a) Analyse four distinct extract weaknesses and relevant evidence work. (4 marks)
(b) Explain why the tool's count agreement is insufficient and propose two source/output validations. (3 marks)
(c) Explain the effect on audit use and two conclusion boundaries. (3 marks)
Show answer and marking
Non-credit errors
- No self-reconciled file count proves complete source population.
- No imported-row coverage equals all-assertion assurance.
Official ICAI concept sourceAUD-G07-D016 · 3 marks
Outsourcing does not remove the IT dependency
A payroll provider maintains the software remotely. The entity's audit file says only "outsourced, therefore no IT understanding needed". The provider changed the version and the entity receives a payroll interface file.
Required: Explain three applied understanding points. (3 marks)
Show answer and marking
Non-credit errors
- No outsourcing eliminates all entity IT work.
Official ICAI concept sourceAUD-G07-D017 · 5 marks
A reconstructed trial balance can still miss the opening data
A CAAT reconstructs a trial balance from current-year transactions. The original ledger includes opening balances, but the extract excludes them. Debits equal credits in the tool. The trainee calls the entity's closing trial balance proved correct.
Required: Explain the legitimate use, missing-data implication, two validations and conclusion limit. (5 marks)
Show answer and marking
Non-credit errors
- No balanced extract proves every closing balance.
Official ICAI concept sourceAUD-G07-D018 · 3 marks
A weekend journal is an investigation lead
An audit tool flags journals posted on weekends. The trainee declares every flagged item fraudulent and every unflagged item safe.
Required: Explain the use and the two conclusion errors. (3 marks)
Show answer and marking
Non-credit errors
- No flag proves fraud; no absence proves safety.
Official ICAI concept sourceAUD-G07-D019 · 5 marks
Digital audit needs a scope explanation
An audit team uses AI to map purchase flows and analytics to identify unusual payments. Its plan says technology now chooses the opinion, removes professional judgement and ensures no relevant risk is missed.
Required: Explain two legitimate benefits, two evidence/judgement limits and one documentation need. (5 marks)
Show answer and marking
Non-credit errors
- No AI chooses an audit opinion or guarantees every risk found.
Official ICAI concept sourceAUD-G07-D020 · 10 marks
Choose controls for different transaction patterns
A wholesaler has 60,000 recurring invoices with predictable missing-field and limit errors. It also has a one-off complex barter transaction outside its existing automated rules. Routine invoices are manually checked by one employee, with skipped reviews during busy days. The automated exception report used by the supervisor is incomplete. A trainee proposes either automating everything or abandoning all automated controls.
Required:
(a) Explain suitability for routine invoices and the unusual transaction. (3 marks)
(b) Analyse manual-review risks and the report dependency. (3 marks)
(c) Propose applied evidence work for the redesigned arrangement. (2 marks)
(d) State two reliance/conclusion limits. (2 marks)
Show answer and marking
Non-credit errors
- No one-size-fits-all method or control reliance from a proposal.
Official ICAI concept sourceAUD-G07-D021 · 3 marks
A valid login is not a valid permission
A former accounts employee's login remains active and retains supplier-edit rights. Management says password authentication proves the employee remains authorised.
Required: Explain authentication, authorisation and the applied check. (3 marks)
Show answer and marking
Non-credit errors
- No password authentication proves current edit authority.
Official ICAI concept sourceAUD-G07-D022 · 5 marks
A complete source is not a complete destination
Warehouse dispatch software sends data to billing nightly. The dispatch file includes 240 records. Billing rejects 12 with a changed item-code format, but its dashboard reports only successful imports. No one follows up rejected records.
Required: Analyse the interface understanding, exception, dashboard limit, applied control evidence and audit-use implication. (5 marks)
Show answer and marking
Non-credit errors
- No success-only dashboard proves all source records processed.
Official ICAI concept sourceAUD-G07-D023 · 3 marks
A plausible amount can still be wrong
An application rejects invoice amounts above a reasonableness ceiling. An invoice is below the ceiling but uses the wrong quantity. A trainee says a passed check proves accuracy.
Required: Explain the check, its limit and relevant follow-up. (3 marks)
Show answer and marking
Non-credit errors
- No passing reasonableness rule proves all input accuracy.
Official ICAI concept sourceAUD-G07-D024 · 5 marks
A job ran, but only half the batches did
An accounting scheduler marks the night's processing complete after one job succeeds. A dependent posting job failed, leaving two approved batches unposted. The file contains no retry or reconciliation evidence.
Required: Explain the general-control objective, dependency risk, two evidence directions and the conclusion limit. (5 marks)
Show answer and marking
Non-credit errors
- No parent-job success proves downstream completeness.
Official ICAI concept sourceAUD-G07-D025 · 10 marks
A new application needs more than a launch announcement
A distributor replaces its inventory application. The project skipped design review; sales-unit conversion rules were never tested. The installed configuration differs from the accepted build. Staff receive broad administrator rights to fix launch issues, and the first interface run rejects records. Management asks the auditor to rely on all new controls because the launch was approved.
Required:
(a) Analyse four implementation/support weaknesses with evidence directions. (4 marks)
(b) Explain two effects on control and system-information reliance. (2 marks)
(c) Set out two appropriate applied testing responses. (2 marks)
(d) State two boundaries. (2 marks)
Show answer and marking
Non-credit errors
- No approved launch proves all controls or data reliable.
Official ICAI concept sourceAUD-G07-D026 · 3 marks
The rule no longer covers the transaction
A company adds multi-currency orders, but an automated limit rule still compares foreign-currency numbers directly with a domestic-currency limit. Management says last year's successful test is sufficient.
Required: Explain necessary change, actual-rule evidence and the reliance limit. (3 marks)
Show answer and marking
Non-credit errors
- No unchanged-rule reliance despite changed transaction conditions.
Official ICAI concept sourceAUD-G07-D027 · 5 marks
An unchanged screenshot is a narrow piece of evidence
A December screenshot shows an application check enabled. The administrator could change the check during the year, and change records are not inspected. The trainee states the check operated unchanged from April to March.
Required: Explain the screenshot's scope, change/access dependency, period implication, applied work and documentation limit. (5 marks)
Show answer and marking
Non-credit errors
- No one-date configuration screenshot proves full-year operation.
Official ICAI concept sourceAUD-G07-D028 · 5 marks
Recalculation tests the formula, not every assumption
A CAAT recomputes depreciation using supplied asset costs, dates and rates. Its calculations agree with management's file. The team has not assessed whether those supplied values are correct or the rule matches the relevant asset circumstances.
Required: Explain the use, three validation needs and the assurance limit. (5 marks)
Show answer and marking
Non-credit errors
- No mathematically matching output proves all inputs or assertions.
Official ICAI concept sourceAUD-G07-D029 · 10 marks
Use analytics to investigate a control deficiency
A payment approval control was disabled for part of the year. A CAAT finds payments above the configured limit during that period. The extract includes only one business unit, uses the current limit instead of historical limits and includes both original and reversed entries. A trainee labels the sum of all flags as fraud loss and says unflagged payments need no attention.
Required:
(a) Explain the legitimate audit use and three data/rule weaknesses. (4 marks)
(b) Propose three distinct applied evidence responses. (3 marks)
(c) Explain three conclusion boundaries. (3 marks)
Show answer and marking
Non-credit errors
- No flag total equals fraud loss; no one-unit analysis equals whole entity.
Official ICAI concept sourceAUD-G07-D030 · 10 marks
Migration, legacy records and manual review
An entity moves from a local accounting system to a cloud application on 1 January. The migration includes closing balances but omits supporting transaction records needed for the intended audit tests. An interface still sends legacy transactions after cutover, and a manager compares cloud reports to an old spreadsheet populated from those same reports. No independent reconciliation or migration-test results are available. The cloud provider also maintains the application.
Required:
(a) Identify four applied understanding/data concerns. (4 marks)
(b) Explain the review weakness and two evidence directions. (3 marks)
(c) Explain period coverage and two conclusion limits. (3 marks)
Show answer and marking
Non-credit errors
- No circular same-source reconciliation establishes independent reliability.
- No cloud configuration proves legacy-period operation.
Official ICAI concept source